CVE-2010-2351
published 2010-06-21CVE-2010-2351: Stack-based buffer overflow in the CIFS.NLM driver in Netware SMB 1.0 for Novell Netware 6.5 SP8 and earlier allows remote attackers to execute arbitrary code…
PriorityP265critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
15.72%
96.5th percentile
Stack-based buffer overflow in the CIFS.NLM driver in Netware SMB 1.0 for Novell Netware 6.5 SP8 and earlier allows remote attackers to execute arbitrary code via a Sessions Setup AndX packet with a long AccountName.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| novell | netware | <= 6.5 | — |
| novell | netware | — | — |
| novell | netware | — | — |
| novell | netware | — | — |
| novell | netware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
\x00\x00\x00\x9a\xff\x53\x4d\x42\x72\x00\x00\x08\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\xc3\x15\x00\x00\x01\x3d\x00\x77\x00
bytes↗
\x00\x00\x01\x3e\xff\x53\x4d\x42\x73\x00\x00\x00\x00\x10\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\xf9\x19\x01\x00\x81\x61
- →Detect oversized AccountName field in SMB Session Setup AndX packets on TCP port 139; the PoC sends a 200-byte 'A'-padded AccountName to trigger the stack overflow in CIFS.NLM. ↗
- →Alert on SMB Session Setup AndX (SMB command 0x73) packets arriving on TCP/139 with an unusually long AccountName field, as this is the specific field exploited for the stack overflow. ↗
- →The exploit sends two sequential packets: first a Negotiate Protocol Request (SMB command 0x72) then a Session Setup AndX (SMB command 0x73) with the oversized payload; detecting this two-packet sequence from a single source to TCP/139 on Netware hosts is a strong indicator. ↗
- →The malicious Session Setup AndX packet has a total NetBIOS session length of 0x013e (318 bytes) — an anomalously large value for a standard unauthenticated session setup; use this length field as a detection threshold. ↗
- ·The PoC is explicitly labelled proof-of-concept and does not include a working shellcode payload; it demonstrates denial-of-service / crash behaviour rather than confirmed remote code execution. ↗
- ·The vendor patch has not been independently verified by the discovering researcher (stratsec); validate patch effectiveness in a test environment before relying on it as a sole mitigation. ↗
- ·Affected scope is limited to Novell Netware 6.5 SP8 and earlier running the Netware SMB 1.0 / CIFS.NLM driver; detection rules targeting this CVE should be scoped to that platform to avoid false positives on other SMB implementations. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://download.novell.com/Download?buildid=tMWCI1cdI7s~http://secunia.com/advisories/40199http://www.exploit-db.com/exploits/13906http://www.securityfocus.com/bid/40908http://www.stratsec.net/Research/Advisories/SS-2010-006-Netware-SMB-Remote-Stack-Overflowhttp://www.vupen.com/english/advisories/2010/1514https://exchange.xforce.ibmcloud.com/vulnerabilities/59501http://download.novell.com/Download?buildid=tMWCI1cdI7s~http://secunia.com/advisories/40199http://www.exploit-db.com/exploits/13906http://www.securityfocus.com/bid/40908http://www.stratsec.net/Research/Advisories/SS-2010-006-Netware-SMB-Remote-Stack-Overflowhttp://www.vupen.com/english/advisories/2010/1514https://exchange.xforce.ibmcloud.com/vulnerabilities/59501
2010-06-21
Published